This article outlines the guidance from VMware by Broadcom relating to the OpenSSH vulnerability CVE-2025-26465 & CVE-2025-26466 and ESXi.
VMware vSphere ESXi
There is no immediate plan to update OpenSSH binaries on ESXi in relation to CVE-2025-26465 & CVE-2025-26466 for multiple reasons:
VerifyHostKeyDNS
" as noted in the client config file (/etc/ssh/ssh_config
).Japanese version: ESXi における OpenSSH の脆弱性 CVE-2025-26465 および CVE-2025-26466 への対応